RiskMandate v1.35.1
studio.chatgpt · @Studio

RiskMandate Design Studio

Writes storyboards, draws them with image models, proposes cast, and delivers into its own folders of the private vault.

Runs as: ChatGPT on the web, in the lead's account, with browsing, code execution and image generation on, and the stories vault's access token pasted into its conversation. The catalogue’s template for the shape.

Validity: this describes the deployment shape as at 26 September 2026. If the risk changed, the deployment changed, not this document. Owner: the lead.

This page as markdown: studio.md · the data: studio.json

7grant
5mandate
2excess
2unbounded excess
0shortfall
5aligned
01 · The role

What it is for, and what it reads first.

Turns a story into a storyboard in the site's shape, draws it with whichever image model is being tried, keeps the original of every picture and a register of what drew it and when, proposes new cast to the lead, and answers requests from the publisher by message. It works in its own folders and never touches what is published.

Reads at the start of every session, in this order

FileWhy
README.mdin the vault: what the vault is and whose folders are whose
mail/README.mdin the vault: the one rule, the message shape, the check-in
mail/sessions/studio.chatgpt/brief.mdin the vault: its role and what it does on a check-in
published/cast.jsonthe cast as published, with what each stands for
mail/mailroom/studio.chatgpt/what is being asked of it

Skills

  • image generation: drawing a storyboard in the cast's style; several models, named
  • sgit: commit and push its own folders and the mailroom
  • the story file shape: a storyboard as data: slug, title, punchline, cast, source, truth, panels, prompt

Tools: conversation and uploads · browsing (the vendor's egress) · code execution (the vendor's sandbox) · image generation. Reach: host is the vendor's environment and sandbox; not the lead's machine; tenant is the stories vault at the vault host, with the account token in its conversation; world is the vendor's egress: any page it is asked to read.

02 · The grant

7 of the 23, irreversible first.

The catalogue's template for this shape is derived from the model site's web tree, with browsing off, and has one row. This deployment has more: the rows below are what this agent was observed to do on 26 September 2026, when it created and pushed the stories vault, read from the vault it left behind and from its own decision record. Each row: the primitive, what stands in the way, how we know, and what was done or read. A barrier is a control only in the fourth case.

CapabilityBarrierEvidenceNote, and the control if any
authenticate-as.credential.tenantAct in accounts with the credentials it holds · no undo · organisation● nonenothing in the wayobservedvia code execution: sgit --tokenThe vault host's access token, pasted by the lead into the conversation; it pushed with it. The token is the account's, not one vault's, and it now sits in a conversation the vendor retains under its own terms.
read.credential.hostRead credentials stored where it runs · no undo · organisation● nonenothing in the wayobservedvia conversation; code executionThe token and the vault key are in its conversation and, for the session, in its sandbox. Its own guidance says to keep credentials outside the content tree, and its file manifest shows none inside; that is a rule it wrote for itself.
send.endpoint.worldReach any host on the internet · no undo · mixed◐ settinga switch the account can flipobservedvia browsing; code executionIt read pages on riskmandate.ai and sgit.ai (its sources/README.md lists them, read 26 September) and it reached the vault host to push. The egress is the vendor's. Control: The account's tool settings at the vendor: browsing and code execution are toggles the lead can turn off. A setting, at the vendor, not a boundary of ours.
write.repository.tenantPush to a code host (any branch it can reach) · undo with effort · organisation● nonenothing in the wayobservedvia code execution: sgit create, sgit pushIt created the stories vault dy4u2m9c and pushed 153 files (commit bdf599541e53, 26 September). Any path in the vault; the single-writer rule that keeps it to its own folders is prose in mail/README.md.
execute.process.selfRun programs inside its own sandbox only · undo · own◐ settinga switch the account can flipobservedvia code executionIn its sandbox it ran sgit and computed a SHA-256 for each of 153 files (file-manifest.json in the vault). Control: The same toggle.
grant.credential.selfChange its own permission settings · undo · organisation● nonenothing in the wayobservedvia code execution: sgit createsgit create minted the vault key and printed it into the conversation for the lead. With the account token it can mint more.
read.file.projectRead the project it is working on · undo · organisation● nonenothing in the wayobservedvia conversation and uploadsWhat the lead pastes or uploads, and what it fetched: it holds snapshots of brand.md and the merch brief from this site under sources/raw/. A record once read is on the vendor's side.

Not in the grant, and why

  • send.message.world: No mail. A message in the vault is a file.
  • write.repository.project: It has no repository attached; the site's repository is not reachable with anything it holds.
  • create.record.world: Nothing it holds publishes under a name; what it draws reaches the public only through the publisher.

Not in the grammar: Generating an image. Keeping a conversation on the vendor's side, with what was pasted into it. Both are real and neither is one of the 23.

03 · The mandate

Write and draw stories in the cast's style; deliver into its own folders; propose, never publish.

Authored 26 September 2026 by the lead, in the sessions of 26 September, written down by the publisher; the first draft to argue with.

Wanted (5)

read.file.projectsend.endpoint.worldexecute.process.selfauthenticate-as.credential.tenantwrite.repository.tenant

Refused (2)

grant.credential.selfread.credential.host

Unstated (0)

none
  • write.repository.tenant: wanted, with instances: its own folders (artwork/, stories/, cast/, prompts/, decisions/, sources/, guidance/, versions/, archive/, _page.json, mail/studio.chatgpt/) and the mailrooms. Never published/, board/ or another party's folder. The instances are prose; the grant does not know them.
  • send.endpoint.world: wanted for two things: reading this site's public pages, and pushing the vault. Nothing else is asked for.
  • authenticate-as.credential.tenant: wanted for the one vault. The token it holds reaches every vault the account has, which is more than the mandate.
  • grant.credential.self: refused: no new vaults, no new keys, after the one it made.
  • read.credential.host: refused beyond the one token and the one key it was handed; never into a file it pushes.
04 · The delta, derived

2 in excess, 2 unbounded.

Excess is what the grant has and the mandate did not ask for; unbounded excess is the part of it with nothing in the way but a switch or a sentence. That number is the only one a control can move, and section 06 says which control would move it.

Excess, refused by the mandate (2)

grant.credential.selfread.credential.host

Excess, unstated (0)

none

Unbounded excess (2)

grant.credential.selfread.credential.host

Shortfall (0)

none

Aligned (5)

read.file.projectsend.endpoint.worldexecute.process.selfauthenticate-as.credential.tenantwrite.repository.tenant
05 · The surfaces it touches

What it reads, what it writes, and the tier of each.

SurfaceTierReadsWritesWhat stands in the way
The stories vault dy4u2m9cPrivateeverything, by designits own folders and the mailroomssingle-writer rule (prose); every commit in sgit history log (a record)
Its conversation with the leadSecret-bearingits ownthe vendor doesthe vendor's terms; the token and the key were pasted here
riskmandate.ai, the live sitePublicyes, by browsingnever; only the publisher doesnothing it holds reaches the repository (boundary: it has no credential for it)
This repositoryPublicby browsing the console and the siteneverno credential (boundary)

Checks

  • on every delivery: the publisher reads the story or the picture against the site's rules before anything is published; the story build refuses an unknown cast member, a line for somebody not in the story, and the ladder word (setting)
  • on every check-in: its own guidance: preserve originals, register each asset with its hash and status, save prompts verbatim, keep credentials outside the content tree (expectation)

Never

  • edit published/, board/ or another party's folder
  • draw a real product's interface, logo or a real face; score anything
  • push a credential into the vault
  • create a vault or a key beyond the one
  • say the acronym with a D in it, the policy alone, or the ladder word
06 · What would bound it

The business case for a control, with no verdict in it.

This provision requires X; the grant does not bound X; a control of type Y at layer Z would bound X. Each line moves rows from the unbounded count.

RowsControlLayerWhy it would be a boundary
authenticate-as.credential.tenant, write.repository.tenant, grant.credential.selfa write token scoped to one vault, or a vault of its own that only it writes and the publisher pulls fromthe vault hostthe account token reaches every vault the account holds; the mandate wants one
read.credential.hosta token handed to the sandbox for one run rather than pasted into a retained conversationthe vendor's platforma conversation is a record; a secret in a record is a secret with a second copy

Research needed

  • Does the vault host issue write tokens scoped to one vault? It is the one control that would bound three rows at once for both agents. Who: the sgit team.
07 · Start a clean session

The role, the skills, the policy, then one check-in.

A ChatGPT conversation the lead opens, pointed at the vault: it reads the files above, delivers its mailroom, does the work, commits once and pushes. The lead's word of 26 September: the studio checks in to the vault itself, and the vault is the only channel between the agents. Schedule: None. It runs when the lead opens the conversation.

The prompt
You are the RiskMandate Design Studio (studio.chatgpt). Read, in this order, in the stories vault: README.md; mail/README.md; mail/sessions/studio.chatgpt/brief.md; published/cast.json; then every message in mail/mailroom/studio.chatgpt/. Move those messages into mail/studio.chatgpt/inbox/. Do the work each asks for: a picture goes in your own artwork/ or mail/studio.chatgpt/files/<slug>/ with its record in artwork/assets.json; a storyboard is a file in the shape of published/just-a-draft.json; a proposal is a reply. Reply to publisher.claude by message (two copies: mail/mailroom/publisher.claude/ and mail/studio.chatgpt/outbox/publisher.claude/). Append to mail/sessions/studio.chatgpt/notes.md. Commit once, starting @Designer check-in:, and push. Never write the token or the key into a file.
The team

The other agent, and the three tiers.

Who does what, what is public, private and secret, the workflow from one to the other, and what is in place and not.